Business, crime, Security

ASOS confirms data breach after “HACKED” in-app notifications

Asos confirmed an "unauthorised customer notification" was sent out via its app on Tuesday, after users raised alarm. Image source, Getty Images By Joe Tidy, Cyber correspondent, World Service and Liv McMahon, Technology reporter Published 6 October 2026, 10:49 BST Updated 2 hours ago Asos says it is investigating "unauthorised activity" involving third-party platforms it uses after customers received a notification from its app sent by hackers. Dozens of people told the BBC they received the strange "ASOS HACKED" message from the clothing and beauty store's app on Tuesday morning – with some saying it left them "scared" to open the app.

The notification was addressed to the company's data protection officer and IT teams in what cyber security experts said looked like a "brazen" extortion attempt. Asos acknowledged the "unauthorised customer notification" on Tuesday afternoon, saying some "basic personal information" may have been accessed. In an email to customers on Tuesday night, the company apologised and urged customers not to engage with the notification.

And it said the website and app are "operating as usual" promising customers they can "shop with confidence" while it investigates the incident. The company has not as of yet informed the UK's data watchdog, the Information Commission's Office (ICO), about any breach. Exactly how many Asos customers received the notification on Tuesday remains unclear, but Google's Play store says the ASOS app has been downloaded to android devices more than 10 million times.

The British retailer has a substantial global footprint – serving around 17 million customers each year across more than 150 markets. Some Asos app users in Australia, France, Sweden and the Republic of Ireland had also received the notification, according to local reports on Tuesday. Hackers seeking to pile pressure on potential victims by informing their customers is rare, as most extortions happen in private, so this incident may go down as a significant moment in cyber-attack history.

UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States.

ASOS has confirmed that third-party platforms used to communicate with customers were accessed without authorization and says basic personal information, including names and contact details, may have been exposed. The company is now displaying an in-app notice telling customers to disregard the unauthorized push alert and not to click or engage with the external third-party link it contained.

Warning about notification now shown in ASOS app However, the company has not confirmed the threat actor's claim that its Snowflake environment was compromised or disclosed how many customers may be affected. ASOS says it does not believe payment-card information or account passwords were impacted.

If you have any information regarding this incident or other undisclosed attacks, you can contact us confidentially via Signal at 646-961-3731 or at tips@bleepingcomputer.com. Hackers abuse ASOS mobile app The notifications began appearing at about 5:00 a.m.

ET on Tuesday, with multiple BleepingComputer readers contacting us after receiving the alerts on their phones. "ASOS HACKED," reads the notification seen by BleepingComputer.

"Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." "ASOS HACKED" notification sent via the official ASOS mobile app The notification directs ASOS to a Telegram channel operated by a threat actor calling itself the "Xuanye group." In messages posted to the channel Tuesday morning, the threat actor claimed the breach did not affect payment information.

The attackers later published a "FINAL STATEMENT," claiming that they stole customer information in the attack. "The affected organisation's app is safe to use.

The incident involves customer information, it is safe on our server, and it will not be touched for a designated period," reads the group's message. "Considering the current situation regarding incident disclosure in the cyber security landscape, you can thank us for our generous clarity regarding this incident." The group did not disclose what customer information was allegedly stolen, how many customers were impacted, or provide evidence showing that it had compromised ASOS's Snowflake environment.

BleepingComputer attempted to contact the threat actors about the breach, but the only contact point required payment. We did not continue as it is against our editorial guidelines to pay for information.

Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Shares in the company fell by around a tenth on Tuesday. Charlotte Wilson, head of enterprise at cyber-security firm Check Point, called it a "deeply serious" and "brazen" attack whereby the hackers had apparently "turned Asos' own app into their ransom note".

But she told the BBC that Asos customers should not be "scared and frightened" – encouraging those worried to change their passwords, avoid clicking on the notification's link and be cautious about possible scam emails or texts. What can I do to protect myself after 'Asos hacked' message?

Published 44 minutes ago Extortion message Image caption, The message popped up on many Asos app users' home screens on Tuesday morning Users of the Asos app appeared to have received the alarming notification at around 10:00 BST on Tuesday. Headlined "ASOS HACKED" and addressed to the company's data protection officer and IT teams, it said: "We have fully compromised the Snowflake instance." "Engage with us, or we will leak it," it added, before linking to a Telegram channel.

The message left many ASOS customers confused. "At first I thought it was an ad or a fun promotion like 'ASOS HACKED get 50% off everything for a limited time only'," Jodie, an analyst from Edinburgh, told the BBC.


Discover more from ChuckysCarnage

Subscribe to get the latest posts sent to your email.

Leave a comment